Legal document

Privacy Policy

What we collect, why, for how long, who touches it, and how you stay in control. In sentences, not clauses.

The essentials

Your stack inventory is used for one thing only: filtering the CVE feed so that we send you only what concerns you. It is not sold, not used to train a model, and not shared with any third party. It is hosted in France, and you can export or delete it whenever you want.

Who processes your data

The data controller is the publisher of the site, identified in the legal notice. For any question about your data or to exercise your rights: [email protected].

What we collect, and why

No other category of data is collected by the service.
DataWhyLegal basisRetention
Account: email, name, hashed password, 2FA secretIdentify you and secure accessPerformance of the contractLifetime of the account, then 30 days
Stack inventory: vendors, products, versionsMatch published CVEs against your componentsPerformance of the contractLifetime of the account, immediate deletion on request
Alerts, cases, commentsTrack how a vulnerability is handled as a teamPerformance of the contractLifetime of the account
Audit log: actor, action, timestampTrace sensitive actions, respond to an auditLegitimate interest (security)30 days (Basic, Plus) · 2 years (Pro) · unlimited (Enterprise)
Technical logs: IP address, user agentDetect abuse, diagnose outagesLegitimate interest (security)12 months
Billing: company name, address, VAT numberIssue and retain invoicesLegal obligation10 years (French Commercial Code)
Audience measurement, if you accept itUnderstand which pages are usefulConsent13 months

Our processors

We have only three, and all of them process your data in the European Union:

  • Hosting: infrastructure located in France (Paris region). No access from outside the EU.
  • Payment: Paddle, which acts as merchant of record and processes billing data. We never see your card number.
  • Email delivery: an email delivery provider established in the EU, for alerts and service messages.

No data is transferred outside the EU. If that were to change, the list above would be updated and customers notified before the switch.

What we don't do

  • We do not sell any data, to anyone, in any form.
  • We do not use your inventory, alerts or comments to train a machine learning model.
  • We set no advertising trackers, and no audience measurement trackers before you consent.
  • We do not look at the content of your account unless you explicitly ask us to for support, and that access is then recorded in the audit log.

Your rights

You have the right of access, rectification, erasure, restriction, objection and portability. A full export of your data is available from the application, without writing to us: this is the most direct form of the right to portability. For the other rights, write to [email protected]; we respond within one month. You may also lodge a complaint with the CNIL.

Security

AES-256 encryption at rest, TLS 1.3 in transit, mandatory TOTP two-factor authentication, short-lived access tokens, login attempt limiting, isolated data network, comprehensive audit log. In the event of a data breach likely to result in a risk, we notify the CNIL within 72 hours and inform the individuals concerned.

Data processing agreement

When you use the service, we act as a processor for the personal data you store in it. A data processing agreement (DPA) compliant with Article 28 of the GDPR can be signed on request: request it, with your own template if you have one.

Changes

Any substantial change to this policy is announced to account holders by email at least thirty days before it takes effect. The version date appears at the top of the page.

Also read the Terms of Use